Skip to content

ci: let bwrap create user namespaces on the runner so the sandbox test runs - #1209

Merged
ZhuchkaTriplesix merged 1 commit into
devfrom
ci/bwrap-enable
Oct 9, 2026
Merged

ZhuchkaTriplesix merged 1 commit into
devfrom
ci/bwrap-enable

Conversation

@ZhuchkaTriplesix

Copy link
Copy Markdown
Member

Refs #1207

Diagnosis

The diagnostics run (#1208) showed the cause on the runner:

bwrap: setting up uid map: Permission denied

Ubuntu 24.04 blocks unprivileged user namespaces through AppArmor, so bwrap cannot start, and the sandbox test skipped with "bwrap is not usable here".

Change

  • In the test job, after installing bubblewrap: sudo sysctl -w kernel.apparmor_restrict_unprivileged_userns=0. The setting applies to the CI VM only; the shipped app is not affected.
  • The temporary diagnostics step is removed.

Risk to watch

If the sandbox test now runs and fails, the sandbox lets a write reach the host. That is a finding to fix, not a reason to skip the test again.

…t runs

bwrap failed with "setting up uid map: Permission denied": Ubuntu 24.04 runners
block unprivileged user namespaces through AppArmor. The sandbox test skipped
for that reason, so its check never ran. The setting is relaxed on the CI VM
only, in the test job, and the temporary diagnostics step is removed.
@ZhuchkaTriplesix
ZhuchkaTriplesix merged commit 7450ccc into dev Oct 9, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant